|
[x]
Posted via EE Mobile
|
|
| Search, ask, and monitor your questions on the go with EE Mobile. Visit Experts Exchange from your mobile device and never be out of touch again. |
|
|
|
|
Asked by MMKPN in Intrusion Detection Systems (IDS), Windows Network Security, Microsoft Operating Systems, Computer Hardware, Miscellaneous Security
I am daily getting "USB_Registry_Activity" from HIDS for a device daily at same time, but no USB is connected to the server and no scheduled services are running at that time. can you tell me what could be the problem.
RULE_NAME="USB_Registry_Co
nnect_Acti
vity
PROCESS_NAME="services.exe
"
DESCRIPTION="Watched Registry CREATE operation on \HKEY_LOCAL_MACHINE\SYSTEM
\ControlSe
t001\Enum\
USB\ROOT_H
UB\4&73530
27&0\LogCo
nf" OTHERINFO=""
20091111-EE-VQP-92 - Hierarchy / EE_QW_3_20080625